Export SqlServer credensqlserver to facilitate your intranet penetration
As mentioned in the netspi blog, you can export the creden。 added later in sqlserver after logging on to the DAC. According to msdn, these creden。 are generally windows user
LG Mobile Phone Authentication Bypass Vulnerability, remote control of mobile phone
Security researchers recently discovered a very serious vulnerability in LG Mobile Phones. Attackers can control LG Mobile phones without any physical access.
Glibc Heap Buffer Overflow Vulnerability (CVE-2015-1473)
Release date:Updated on:
Affected Systems:GNU glibcDescription:Bugtraq id: 72499CVE (CAN) ID: CVE-2015-1473
Glibc is the libc library released by GNU, that is, the c Runtime Library. Glibc
Rsync path Spoofing Vulnerability
Release date:Updated on:
Affected Systems:Samba rsync 3.1.1Description:CVE (CAN) ID: CVE-2014-9512
Rsync is a fast incremental file transfer tool used for internal backup on the same host.
Rsync 3.1.1 has the
PolarSSL was found to contain high-vulnerability Security Vulnerabilities
Security Report from securityweek: PolarSSL has a high vulnerability that can cause DoS attacks and may be used for remote code execution.
PolarSSL is used in many projects,
A Research on a suspicious Payload
Letter difference
When we find suspicious Payload, we will try to study it. Maybe they won't have any problems during our detection, but it doesn't mean they have no problems.
A Payload found under a website is an
Another method of gsm hack: RTL-SDR.0x00 background
All content in this article is for study purposes only. Do not use it for illegal purposes. Illegal eavesdropping is a serious illegal activity in most countries.
This article only describes the
XSS vulnerability search and detection
1. Black box testing
Black box testing refers to testing the system without knowing the code and running status of the system. In the detection of XSS vulnerabilities, we can simulate hacker attack methods and
Bind_param principle of mysql binding parameter and anti-SQL InjectionAssume that there is a row in our user table. The username field is username. The value is aaa. The password field is pwd. The value is pwd ..Next we will simulate a user login
I took the entire sharded cluster and its solution through unauthorized access to mongodb
Mongodb document database. Building a cluster to process massive data has very good results.
The problem first originated from unauthorized access to
See how I can bypass Baidu xss to fix problems from a reflection to storage (blind cookies)
With the ID of a white hat in wooyun. Write XSS code in the control panel. Let's take a look at it first ~ This code:
It does not filter out <> and
Mao10CMS v3.0.2 an interesting SQL injection.
User registry.
Public function submit () {$ ip_false = M ('option')-> where ("meta_key = 'IP _ false' AND type = 'user '") -> getField ('meta _ value', true); if ($ ip_false & in_array (mc_user_ip (), $
China Telecom ADSL an advertisement push system SQL Injection
This type of hard advertisement often pops up when you open a webpage.
URL: http: // 121.32.136.50: 701/gz_20151128/guangzhou/20141028/BadwebRemindPage. aspx? Param = Signature =I
Oriental fashion driving school SQL Injection getshell cross-database N multi-data
Today, the car appointment time is queried, but the webpage cannot be opened... 3G and WiFi cannot go in... I had to open it and try again.The Oriental fashion
SQL injection without single quotes or commas
0X00 background
Audit cms found an environment like this:
$ L_id = get ('arr', 'l _ id'); $ ids = explode (',', $ l_id );
Concatenate the array requests in post, and then separate them with commas (,)
Map map unauthorized access to a platform database (leakage of user information)
Map map unauthorized access to a platform database (leakage of user information)
42.121.15.217
/* 0 */{"_ id": ObjectId ("547045624159313d28dc0000"), "sign_
[Security] (1): Hacker programming skillsI have been in contact with the security field for four years. I have been familiar with many aspects, but I am not proficient. I feel that my strength is lacking, therefore, I decided to start learning the
Adversarial ROBOT: Build a WAF that combines front and back ends
We have introduced some man-in-the-middle attack solutions that combine front and back ends. Due to the particularity of Web programs, the participation of front-end scripts can
SQL Injection caused by improper ThinkPHP patch repair
This is ThinkPHP patch for this injection: https://github.com/liu21st/thinkphp/commit/23c6e130ce75f2132e5b48699363a75ed28e15b2
}elseif(is_array($val) && isset($_REQUEST[$key]) &&
Another getshell in the U-mail system
An improper handling of a certain part of the U-mail system leads to getshell
Version: U-Mail for Windows V9.8.57Test account: hello0001@fuck.comTest HOST: windows server 2003 + IIS6 [windows host configuration
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service